Security for the rest of us.
Detection, investigation, and incident response for the businesses that need it most. Run by people who kick out attackers for a living.
The difference
Every case is handled by a human.
Most managed, large-scale security service providers route security events through a language model and hope it sorts the real threats from the noise. We've watched that approach quietly fail.
We use automation where it removes toll on the practitioner, enrichment, response, evidence collection to name a few. Every case is triaged, investigated, and closed by a human who is accountable for the call.
Credentials
Unparalleled expertise you'd normally have to fly in.
We hold the GIAC GCFA and GSOC, gold-standard security certifications that define digital forensics, detection engineering and security operations.
Our team's background reaches from protecting private banks and critical infrastructure in Europe, all the way to securing airlines and healthcare providers across Latin America. The same standard that used to guard the biggest players now protects the businesses that need it most.
What we do
Detect, investigate, respond.
Detect
Behavior-based endpoint detection watched 24/7/365, backed by continuous threat hunting, not just automated alerts. When something looks wrong, it's already in front of a senior analyst, not a first-tier queue that has to escalate, wait, and re-learn your environment from scratch.
Investigate
Every detection is triaged and investigated in full context, critical and high-severity cases inside 30 minutes, day or night. When a case needs to go deeper, our own DFIR specialists take over: memory, persistence, and process history, backed by GIAC-certified expertise (GCFA, GSOC).
Respond
Contain, eradicate, remediate. Endpoints can be isolated and threats removed within minutes. Because the same team investigates and responds, nothing gets lost in a handoff. For a real incident, you get a full report: what happened, what we did, and how to stop it happening again.
Response times we stand behind
Running a smaller team? We offer a lighter, business-hours tier on the same detection platform, priced for smaller environments, critical and high-severity alerts are still handled within 4 hours. Ask us what fits.
Why Duntze
The case for working with us.
We are a small team of experienced practitioners.
The people watching your environment are the same people who respond when it matters. You focus on running your business, we'll take care of security.
Priced for the businesses we serve.
Enterprise-grade protection without the enterprise price tag or the fine print. You pay for coverage that fits your size. No minimums built for companies ten times bigger, no surprises on the invoice.
Regional context, international standard.
Years of hands-on DFIR across Europe and Latin America. Threats here have their own shape, the response should be built for it.
Field notes
Notes from the field.
SVG smuggling: an infostealer disguised as a court summons
An .svg file with embedded JavaScript kicked off a social-engineering chain ending in a downloaded infostealer. No macro, no exploit, just a file type nobody expects to run code.
DFIRVibecoded RAT? A LOLBins chain hiding behind an HTA file
A phishing lure impersonating Colombian authorities chained three legitimate Windows binaries to deploy a RAT that hid its C2 traffic in the User-Agent header.
DFIRAnatomy of a ClickFix-to-RAT campaign: trojanizing Electron's app.asar
A signed binary, clean DLLs, and one tampered app.asar archive: how a fepafut[.]com ClickFix lure led to a persistent RAT that inherited draw.io's trust chain.
DFIRGet in touch
Tell us what you're protecting.
Let's talk security. A short conversation is usually enough to tell whether we're the right fit.
contact@duntzesecurity.com